// legal

Privacy Policy

Last updated 14 August 2026 · OneClik is operated by Innowave GDU India Private Limited

The short version. OneClik carries bug reports from your users to your team. We keep the account data we need to run the business, and we hold report data on your instructions, not our own. We never sell personal data and we never train third-party models on what your users send. Everything below is the long version, and it applies under the EU and UK GDPR, India's Digital Personal Data Protection Act 2023, the California Consumer Privacy Act and comparable law elsewhere.

1. Who you are dealing with

OneClik is a product of Innowave GDU India Private Limited, 4th Floor, KALPAVRUKSHAM, 1780/A, 15th Main Rd, HBR Layout 5th Block, Telecom Layout, Nagavara, Bengaluru, Karnataka 560043, India. Company identification number U72900KA2019PTC127660. You can reach our privacy contact at privacy@oneclik.app.

2. Two kinds of data, two roles

We act in two distinct roles. We are the controller for data we collect directly: account records, billing, support conversations, marketing contacts and website analytics. We are a processor for the report data our customers collect through OneClik. In that case the customer is the controller, decides what is captured, and is responsible for informing their own users and obtaining any consent required. That processing is governed by our Data Processing Agreement, available on request from privacy@oneclik.app.

If you submitted a report through a product that uses OneClik and want to exercise your rights over it, contact that company directly. If you contact us, we will refer you to them.

3. What we hold

You give us: name, work email, job title and company when you create an account; hashed passwords and authentication tokens; billing name, address and tax identifiers; the content of support requests and emails; and your details if you subscribe to product updates or join a beta.

We collect automatically: IP address and approximate location at country level, device type, operating system, browser version, pages viewed, session duration, referring URLs, in-product interactions, and error and performance logs.

Captured in reports, on our customers' instructions: a screenshot, annotation or session recording, console and network logs, device and browser metadata, the page or screen URL, any description the reporter writes, attachments they add, and the authenticated user identifier if the customer has enabled it.

From third parties: billing confirmation from our payment processor, single sign-on profile data from identity providers you choose to use, and aggregate campaign data from advertising and analytics partners.

4. Why we hold it, and on what legal basis

To provide the service — creating accounts, authenticating users, rendering reports, generating AI drafts and root-cause analysis within a workspace, and routing tickets to connected tools. Necessary to perform our contract with you.

To handle billing — processing payments, managing subscriptions and keeping invoices. Necessary for our contract and to meet tax and accounting obligations.

To support and inform you — answering requests and sending service notices or product updates. Our legitimate interest in operating the service; you can opt out of product updates at any time.

To send marketing — newsletters and event invitations, where you have consented. You can withdraw consent from any message.

To improve the product — analysing aggregate usage and performance to fix defects and prioritise work. Our legitimate interest in developing the service.

To keep the service secure — detecting abuse, preventing unauthorised access and investigating incidents. Our legitimate interest in protecting our systems and our users.

To meet legal obligations — responding to lawful requests and complying with accounting, tax and audit requirements.

Where we rely on legitimate interest, we weigh that interest against your rights, and you can object at any time under section 10.

5. Cookies on our website

Our website uses cookies that are strictly necessary for it to function, and analytics cookies that help us understand traffic and measure campaigns. Non-essential cookies are set only with your consent, and you can change or withdraw that consent at any time from the cookie banner or your browser settings. The OneClik widget and SDKs do not set advertising cookies inside our customers' products.

6. Who else touches it

We share data only where it is needed to run the service or where the law requires it. Our subprocessors are contractually bound to protections equivalent to those in this policy, and the current list is available on request from privacy@oneclik.app. It includes our cloud hosting provider, our payment processor Paddle, our email delivery provider, our customer support tooling and our product analytics provider.

We may disclose personal data to competent authorities where we are legally required to. If we are involved in a merger, acquisition or sale of assets, data may transfer as part of that transaction, subject to confidentiality and to notifying you.

Two things we do not do: we do not sell personal data, and we do not use customer report data to train third-party models.

7. Where it lives, and when it moves

Our primary infrastructure is hosted in India, and we operate from India. Where personal data moves out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, and we carry out a transfer risk assessment for each recipient. Enterprise customers with data residency requirements can ask us about regional hosting.

8. How long we keep it

Report data captured through OneClik is retained for the window set by the workspace's plan, from 7 to 90 days, or a custom period on Enterprise, and is then deleted. Customers can delete an individual report or an entire workspace at any time. Account records are kept for the life of the subscription and 30 days after it ends. Billing records are kept for eight years to meet Indian tax and company law requirements. Support conversations are kept for up to three years after resolution, and marketing contact data until you unsubscribe. After these periods data is deleted or irreversibly anonymised.

9. How we protect it

We encrypt data in transit with TLS 1.2 or above and at rest with AES-256. Access to production systems is role-based, requires multi-factor authentication and is logged. We take daily backups, run vulnerability scanning, review access regularly, and require confidentiality undertakings and security training from everyone on the team. Where a breach affects your personal data we will notify you and the relevant authority within the timelines the law sets.

10. Your rights, wherever you are

Whatever law applies to you, the same request line works: write to privacy@oneclik.app. We verify who you are, then respond within one month, or sooner where the law requires it.

You can ask us to confirm what we hold and send you a copy, correct anything wrong or incomplete, delete what we no longer need, restrict how we process it, hand it over in a machine-readable format, or stop processing that rests on legitimate interest or direct marketing. Where we rely on consent, you can withdraw it at any time, and that does not undo what was lawful before.

A few additions by jurisdiction. In India, you may nominate someone else to exercise these rights for you, and you may escalate to the Data Protection Board of India. In the EU and UK, you may complain to your local supervisory authority. In California and other US states with comparable law, you have the right to know, delete, correct and be treated no differently for asking; we do not sell personal information and we do not share it for cross-context behavioural advertising.

11. Children, and links we do not control

OneClik is a tool for software teams. It is not directed at children and we do not knowingly collect data from anyone under 18; if a child's data reaches us, tell us and we will delete it. Separately, our site and product connect to third-party services, including the issue trackers and chat tools you choose to link. Once data arrives there it is governed by their terms, not ours.

12. Changes to this policy

We update this policy when our practices or the law change, and we revise the date at the top. If a change is material we will tell workspace owners by email or in the product before it takes effect.

13. Contact

Innowave GDU India Private Limited
4th Floor, KALPAVRUKSHAM, 1780/A, 15th Main Rd,
HBR Layout 5th Block, Telecom Layout, Nagavara,
Bengaluru, Karnataka 560043, India
privacy@oneclik.app

© 2026 Oneclik. All rights reserved.